博客
关于我
强烈建议你试试无所不能的chatGPT,快点击我
.net 防止sql注入
阅读量:6608 次
发布时间:2019-06-24

本文共 5727 字,大约阅读时间需要 19 分钟。

 public class SqlCheck  

{  
    public SqlCheck()  
    {  
        //  
        // TODO: 在此处添加构造函数逻辑  
        //     
    }  
 
      
    public SqlConnection oconn()  
    {  
        SqlConnection conn = new SqlConnection();  
        conn.ConnectionString = ConfigurationManager.ConnectionStrings["StudyConnectionString"].ToString();  
        //第1种调用的方法   JK1986_CheckSql();  
        JK1986_CheckSql();  
        if ( conn.State == ConnectionState.Closed  )   
        {  
            conn.Open();  
        }  
        return conn;  
    }  
 
 
    public DataTable  getsource(string getds)   
    {  
        SqlConnection conn = oconn();  
        SqlDataAdapter da = new SqlDataAdapter(getds, conn);  
        DataSet ds = new DataSet();  
        da.Fill(ds,"news" );  
        return ds.Tables["news"];  
    }  
      
 
    public static  void JK1986_CheckSql()  
    {  
        string jk1986_sql = "exec↓select↓drop↓alter↓exists↓union↓and↓or↓xor↓order↓mid↓asc↓execute↓xp_cmdshell↓insert↓update↓delete↓join↓declare↓char↓sp_oacreate↓wscript.shell↓xp_regwrite↓'↓;↓--";  
        string[] jk_sql = jk1986_sql.Split('↓');  
        foreach (string jk in jk_sql)  
        {  
            // -----------------------防 Post 注入-----------------------  
            if ( System.Web.HttpContext.Current.Request.Form != null)  
            {  
                for (int k = 0; k < System.Web.HttpContext.Current.Request.Form.Count; k++)  
                {  
                    string getsqlkey = System.Web.HttpContext.Current.Request.Form.Keys[k];  
                    string getip;  
                    if (System.Web.HttpContext.Current.Request.Form[getsqlkey].ToLower().Contains(jk) == true)  
                    {  
                       System.Web.HttpContext.Current.Response.Write("<script Language=JavaScript>alert('ASP.NET( C#版本 )防注入程序提示您,请勿提交非法字符!↓\\n\\nBlog:http://hi.baidu.com/ahhacker86
\\n\\nBy:aa && JK1986');</" + "script>");  
                       System.Web.HttpContext.Current.Response.Write("非法操作!系统做了如下记录 ↓" + "<br>");  
                       if (System.Web.HttpContext.Current.Request.ServerVariables["HTTP_X_FORWARDED_FOR"] != null)  
                        {  
                            getip = System.Web.HttpContext.Current.Request.ServerVariables["HTTP_X_FORWARDED_FOR"];  
                        }  
                        else 
                        {  
                            getip = System.Web.HttpContext.Current.Request.ServerVariables["REMOTE_ADDR"];  
                        }  
                        System.Web.HttpContext.Current.Response.Write("操 作 I  P :" + getip + "<br>");  
                        System.Web.HttpContext.Current.Response.Write("操 作 时 间:" + DateTime.Now.ToString() + "<br>");  
                        System.Web.HttpContext.Current.Response.Write("操 作 页 面:" + System.Web.HttpContext.Current.Request.ServerVariables["URL"] + "<br>");  
                        System.Web.HttpContext.Current.Response.Write("提 交 方 式:P O S T " + "<br>");  
                        System.Web.HttpContext.Current.Response.Write("提 交 参 数:" + jk + "<br>");  
                        System.Web.HttpContext.Current.Response.Write("提 交 数 据:" + System.Web.HttpContext.Current.Request.Form[getsqlkey].ToLower() + "<br>");  
                        System.Web.HttpContext.Current.Response.End();  
                    }  
                }  
            }  
            // -----------------------防 GET 注入-----------------------  
            if (System.Web.HttpContext.Current.Request.QueryString != null)  
            {  
                for (int k = 0; k < System.Web.HttpContext.Current.Request.QueryString.Count; k++)  
                {  
                    string getsqlkey = System.Web.HttpContext.Current.Request.QueryString.Keys[k];  
                    string getip;  
                    if (System.Web.HttpContext.Current.Request.QueryString[getsqlkey].ToLower().Contains(jk) == true)  
                    {  
                        System.Web.HttpContext.Current.Response.Write("<script Language=JavaScript>alert('ASP.NET( C#版本 )防注入程序提示您,请勿提交非法字符!↓\\n\\nBlog:http://hi.baidu.com/ahhacker86
\\n\\nBy:aa && JK1986');</" + "script>");  
                        System.Web.HttpContext.Current.Response.Write("非法操作!系统做了如下记录 ↓" + "<br>");  
                        if (System.Web.HttpContext.Current.Request.ServerVariables["HTTP_X_FORWARDED_FOR"] != null)  
                        {  
                            getip = System.Web.HttpContext.Current.Request.ServerVariables["HTTP_X_FORWARDED_FOR"];  
                        }  
                        else 
                        {  
                            getip = System.Web.HttpContext.Current.Request.ServerVariables["REMOTE_ADDR"];  
                        }  
                        System.Web.HttpContext.Current.Response.Write("操 作 I  P :" + getip + "<br>");  
                        System.Web.HttpContext.Current.Response.Write("操 作 时 间:" + DateTime.Now.ToString() + "<br>");  
                        System.Web.HttpContext.Current.Response.Write("操 作 页 面:" + System.Web.HttpContext.Current.Request.ServerVariables["URL"] + "<br>");  
                        System.Web.HttpContext.Current.Response.Write("提 交 方 式:G E T " + "<br>");  
                        System.Web.HttpContext.Current.Response.Write("提 交 参 数:" + jk + "<br>");  
                        System.Web.HttpContext.Current.Response.Write("提 交 数 据:" + System.Web.HttpContext.Current.Request.QueryString[getsqlkey].ToLower() + "<br>");  
                        System.Web.HttpContext.Current.Response.End();  
                    }  
                }  
            }  
 
            // -----------------------防 Cookies 注入-----------------------  
            if (System.Web.HttpContext.Current.Request.Cookies != null)  
            {  
                for (int k = 0; k < System.Web.HttpContext.Current.Request.Cookies.Count; k++)  
                {  
                    string getsqlkey = System.Web.HttpContext.Current.Request.Cookies.Keys[k];  
                    string getip;  
                    if (System.Web.HttpContext.Current.Request.Cookies[getsqlkey].Value.ToLower().Contains(jk) == true)  
                    {  
                        System.Web.HttpContext.Current.Response.Write("<script Language=JavaScript>alert('ASP.NET( C#版本 )防注入程序提示您,请勿提交非法字符!↓\\n\\nBlog:http://hi.baidu.com/ahhacker86
\\n\\nBy:aa && JK1986');</" + "script>");  
                        System.Web.HttpContext.Current.Response.Write("非法操作!系统做了如下记录 ↓" + "<br>");  
                        if (System.Web.HttpContext.Current.Request.ServerVariables["HTTP_X_FORWARDED_FOR"] != null)  
                        {  
                            getip = System.Web.HttpContext.Current.Request.ServerVariables["HTTP_X_FORWARDED_FOR"];  
                        }  
                        else 
                        {  
                            getip = System.Web.HttpContext.Current.Request.ServerVariables["REMOTE_ADDR"];  
                        }  
                        System.Web.HttpContext.Current.Response.Write("操 作 I  P :" + getip + "<br>");  
                        System.Web.HttpContext.Current.Response.Write("操 作 时 间:" + DateTime.Now.ToString() + "<br>");  
                        System.Web.HttpContext.Current.Response.Write("操 作 页 面:" + System.Web.HttpContext.Current.Request.ServerVariables["URL"] + "<br>");  
                        System.Web.HttpContext.Current.Response.Write("提 交 方 式: Cookies " + "<br>");  
                        System.Web.HttpContext.Current.Response.Write("提 交 参 数:" + jk + "<br>");  
                        System.Web.HttpContext.Current.Response.Write("提 交 数 据:" + System.Web.HttpContext.Current.Request.Cookies[getsqlkey].Value.ToLower() + "<br>");  
                        System.Web.HttpContext.Current.Response.End();  
                    }  
                }  
            }  
 
        }  
    }       
      
}

 

 

来源于: B.B.S.T 信息安全团队 BadBoy网络安全小组

转载于:https://www.cnblogs.com/secbook/archive/2011/12/06/2654922.html

你可能感兴趣的文章
找到一个适合的分布式文件系统之各种分布式文件系统优缺点对比
查看>>
httpd基本配置
查看>>
索引失效的几个原因
查看>>
关于多线程中使用while做循环而不使用if的解释
查看>>
js typoeof用法
查看>>
五险一金,你清楚吗?
查看>>
Ip核_fifo
查看>>
repquota命令--Linux命令应用大词典729个命令解读
查看>>
设置vs解决方案跟随右边cpp
查看>>
Linux Administration
查看>>
rabbitmq 管理及常用命令
查看>>
iphone导航控制器的开发与使用
查看>>
debian python library re-install
查看>>
如何用转义来给JS添加的input元素设置单引号
查看>>
HTTP要被抛弃? 亚洲诚信携手宝塔开启HTTPS加密快速通道
查看>>
6.6 tar打包
查看>>
Spring MVC核心技术
查看>>
TCP协议如何保证传输的可靠性
查看>>
Spring Cloud云架构 - SSO单点登录之OAuth2.0 登出流程(3)
查看>>
软件开发各阶段交付物列表
查看>>